← Back

CVE-2019-3740

nvd nist
Published: Sep 18, 2019Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.

Affected (47)

3 products
Bsafe Cert J
Bsafe Crypto J
Bsafe Ssl J
15 products
Communications Network Integrity
Database
Goldengate
Retail Assortment Planning
Retail Integration Bus
Retail Service Backbone
Retail Store Inventory Management
Retail Xstore Point Of Service
Storagetek Acsls
Storagetek Tape Analytics Sw Tool
Weblogic Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Up to 6.2.4
Before 6.2.5
Up to 6.2.4.1
Configuration B
44 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 13.3.0.0
Version 13.4.0.0
Oracle
Version 7.3.2
Version 7.3.5
Version 7.3.6
Oracle
Version 7.3.2
Version 7.3.4
Version 7.3.5
Version 7.4.0
Version 7.4.1
Oracle
Version 12.1.0.2
Version 12.2.0.1
Version 18c
Version 19c
Before 12.2.0.1.22
Before 19.1.0.0.0.210420
Oracle
Version 15.0.3.0
Version 16.0.3.0
Oracle
Version 14.1
Version 15.0
Version 16.0
Oracle
Version 14.1.3.0
Version 15.0.3.0
Version 15.0
Version 16.0.3.0
Oracle
Version 14.1
Version 15.0
Version 16.0
Oracle
Version 14.0.4
Version 14.1.3
Version 15.0.3
Version 16.0.3
Oracle
Version 15.0.3
Version 16.0.5
Version 17.0.3
Version 18.0.2
Version 19.0.1
Version 8.5.1
Version 2.3
Oracle
Version 10.3.6.0.0
Version 12.1.3.0.0
Version 12.2.1.3.0
Version 12.2.1.4.0
Version 14.1.1.0.0

References (14)

Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.